Skip to content

fix(emulated): pad the input of the inverse hint to NbLimbs - #1855

Open
FlashWayne wants to merge 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/emulated-inverse-short-limbs
Open

FlashWayne wants to merge 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/emulated-inverse-short-limbs

Conversation

@FlashWayne

Copy link
Copy Markdown
Contributor

Field.Inverse fails for a non-constant element that is stored on fewer limbs than NbLimbs(), for example the result of Select between two small constants. Div, Mul, Sqrt and Exp on the same element work.

x := f.Select(b, f.NewElement(3), f.NewElement(5))
f.Inverse(x)

Before: NewHint: inputs missing (r1cs, scs and the test engine).
After: solves, result checked against ModInverse.

computeInverseHint appends the element's limbs as they are, while InverseHint requires 2 * NbLimbs inputs after the header (modulus, then value). computeDivisionHint passes the limb counts explicitly, which is why division is not affected. This pads the value with zero limbs in computeInverseHint, so the hint's input layout is unchanged.

Test: TestInverseShortElement (both branches of the select, test engine + compiled r1cs/scs), fails on master. std/math/emulated, sw_emulated and internal/stats pass.

InverseHint requires the value on NbLimbs limbs, but computeInverseHint
forwarded the element's limbs as they are. An element stored on fewer limbs,
such as a Select between two small constants, made the hint fail with
"inputs missing". Pad the input limbs with zeros before calling the hint.
@FlashWayne
FlashWayne requested a review from a team as a code owner September 29, 2026 05:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant